Overview
This course is designed for Information Security Managers, Officers, Project Managers, and other professionals responsible for implementing, evaluating, and enhancing ISMS across organizations. It covers comprehensive aspects including organizational, physical, and technical security controls, risk analysis, and governance aligned with ISO/IEC 27001 requirements.
Objectives
By the end of this course, leaner will be able to:
- Apply business, customer, and service provider perspectives in security governance
- Conduct information risk analysis, choose suitable controls, and address residual risks
- Implement organizational, technical, and physical information security controls
- Integrate ISMS principles with international standards (ISO/IEC 27001 & 27002)
- Prepare professional ISMS documentation and reporting for audits
Prerequisites
- Successful completion of EXIN Information Security Foundation (ISO/IEC 27001) certification is recommended
- Accredited EXIN ISMP training with practical assignments
Course Outline
- Business, Customer, Service Provider viewpoints on information security
- Risk analysis methods, selecting controls, and dealing with residual risks
- Policies, procedures, incident handling, awareness, roles, and business continuity
- Security architectures, IT infrastructure elements, physical access, and personnel security
- Aligning control implementation with ISO standards, documentation, reporting, and preparation for evaluation